The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure Power Commission <V2.22
- Summary
- A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site.
- Remediation
- V2.22 and later of EcoStruxure Power Commission includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/62980-ecostruxure-power-commission/#software-and-firmware
